How Hackers for Hire Exploit Compromised Electronic Filing Systems, Stolen Credentials and Attack Surfaces Hiding in Plain Site
JUNE 3, 2026 – Written by Jay Lewis Farrow – Legal-Sector Cybersecurity Operator, with forensic contributions by Cyber-N.E.T. Forensics (CNF), Bridge-Gate ESS Division’s Restricted-Access Portal Solutions Unit (RAPS), Cryptographic Cyber-Defense Group (CCDG), and collaborating cyber-defense/security investigation teams.
Beginning around 2010, state and federal courthouse doors across the country were rebuilt digitally. Electronic filing, electronic service, and digital records were adopted to make courts more accessible, improve the efficiency of judicial proceedings, and allow attorneys and self-represented litigants to file court papers without physically visiting a courthouse.
Court technology, servers, infrastructure, and endpoint computers were upgraded to accommodate this shift. Before digitization, clerks often had to retrieve physical court files and deliver them to judges before hearings. Digital dockets later allowed attorneys and members of the public to monitor the progress of cases and, over time, download PDF copies of court documents.
This transition toward digital dockets, electronic filing, and electronic service of judicial notices, interim decisions, and final orders was welcomed by the overwhelming majority of attorneys, law firms, and other interested parties. The transformation appeared to make judicial proceedings more transparent, affordable, efficient, and uniform.
At the same time, digital filing systems became necessary to address the exponential burdens placed upon judges, judicial staff, and court clerks by increasing litigation, particularly after the 2008 financial crisis and other consequential events.
As with any new technology-dependent system, this transition required attorneys, legal staff, and court personnel to receive training. Users had to learn how to establish login credentials for electronic filing portals, convert documents into uploadable PDFs, ensure service upon the correct parties, and access documents through electronic-service links.
Over time, amendments to judicial administrative orders and other directives in most United States jurisdictions required nearly every court filing to be submitted electronically or conventionally filed with a clerk, who would then scan, upload, and docket the document in the same electronic system or, where appropriate, in a confidential filing environment.
The purposes and utility of this transition from paper files to digital dockets are undeniable. Yet the consequences of implementing these systems without reliable safeguards for system compromise are now emerging as a serious institutional risk. A single point of failure may allow threat actors to exploit, ironically, the concept of “blind justice.”
In practical terms, the digital courthouse door was built so that almost no route to judicial relief exists unless a lawyer’s or litigant’s filing is first digitized and uploaded. That arrangement is manageable during normal operations. It is dangerous during a cyber emergency.
The issue is not that courts use technology. They must. The issue arises when the filing system, service list, email route, portal credential, DNS path, or docketing workflow is itself evidence of compromise. Under those circumstances, the victim may be forced to warn the court through the same digital rail alleged to be under attack.
Paper is not always a genuine fallback. A hand-delivered filing may still be scanned, indexed, docketed, served, and routed through the same electronic environment. If that environment has been compromised, the paper filing may become merely another artifact within a contested data stream.
The National Attorneys Cybersecurity Association, NACABAR, and other judicial-watch organizations have proposed that federal and state courts establish an emergency access channel that bypasses both electronic filing and paper submissions that are digitized before being electronically routed to a judge.
This out-of-band intake protocol would help ensure that evidence of manipulation within a judicial proceeding reaches a judge, special master, designated cyber-integrity officer, or appropriate law-enforcement authority without first passing through the contested system. Such a process would reduce the ability of threat actors to control the ordinary flow of due process.
The proposal may appear to some to be common sense. Others may view it as unnecessary because courts historically relied upon paper filings. Nevertheless, cybersecurity professionals have observed that, outside limited jurisdictions, few meaningful out-of-band procedures exist for alerting a court that documents, evidence, service events, or routing processes may have been tampered with, truncated, delayed, misdirected, or deleted.
The Integrity Risk
The known facts include that threat actors have exploited court and court-adjacent cyber infrastructure for years. In early August 2025, Politico reported a significant breach of the federal judiciary’s electronic filing and records systems. Reuters reported that the Administrative Office of the U.S. Courts had acknowledged that judiciary systems were being targeted by sophisticated and persistent cyberattacks.
Although the full extent of the reported breach was not publicly disclosed, the federal judiciary subsequently announced strengthened protections for its electronic case-management systems.
Initial reporting focused heavily on confidentiality risks, including sealed records, confidential-informant identities, sensitive criminal filings, and law-enforcement materials. This article addresses the companion risk: the integrity of intake, routing, service, and docket identity.
Recent expert reporting has suggested that risks involving federal CM/ECF and PACER systems remain serious and that certain state electronic filing environments may have experienced similar forms of cyberattack since at least 2022.
The recurring concern is that every court filing—whether submitted electronically or conventionally on paper—ultimately becomes digitized. Paper filings are commonly scanned and uploaded into a court database before being routed to a judge. Even emergency submissions involving highly sensitive documents may be uploaded into restricted databases, while the public docket reflects that some form of filing event occurred.
Once an emergency filing and its exhibits have been digitized, recent expert reports suggest that the servers housing those materials may remain within the same broader technical environment under examination. The documents are then routed to the assigned judge and court staff for processing, hearing coordination, or the issuance of judicial decisions.

How the Route Becomes the Target
“We painted ourselves into a cyber corner. We built digital dockets and electronic filing portals with no exceptions,” said one federal judicial official who asked not to be identified because of their involvement in the ongoing investigation.
After reviewing several expert reports authored by organizations and agencies participating within the Joint Cyber Defense Collaborative ecosystem, along with information obtained through interviews, open sources, and filed court documents, the threat assessment appears straightforward and serious.
With very few exceptions—and none identified within the federal district courts’ CM/ECF systems—the only way a party, attorney, or third-party intervenor can deliver court papers, evidence, an emergency motion, or a request for a judicial hearing begins with either electronic filing or conventional paper filing through the clerk’s office. Because both filing methods ultimately result in the digitization and electronic docketing of the submitted materials, there is no out-of-band path for judicial review that avoids the primary intake surface and subsequent routing layers.
The known facts are that threat actors have established persistent footholds within judicial cyber infrastructure, legacy servers, and end-of-life endpoints. They may also have spent years harvesting attorneys’ electronic-filing credentials, giving them the ability to target both the intake and communications-routing surfaces within court and court-adjacent networks.
Although CM/ECF systems vary among federal jurisdictions, just as state electronic filing systems vary, the extent of any compromise—and the ability of threat actors to cause harm, steal information, or manipulate proceedings—remains unclear.
“Even if those statistics or details were available, they would not alter the fundamental systemic failure: no attorney or litigant can reach judicial authority without first having their materials digitized and uploaded into systems known to have been compromised,” said one expert working to contain the “massive” attack first announced by judicial officials in early August 2025.
Put differently, nearly ten months after federal authorities acknowledged substantial, persistent, and serious intrusions into critical systems, an attorney, law firm, or litigant possessing evidence that hackers are targeting legal proceedings may still be required to submit motions and evidence through the contested system—either by electronic filing or by conventional in-person filing that is later digitized.
Evidence of docket manipulation may escape detection by a law firm’s information-technology department. However, dockets obtained directly from court clerks have reportedly contained missing entries for court orders, orders stating that judges could not access emergency filings and exhibits, and subsequent procedural dismissal orders accompanied by hundreds of pages added to the docket record without a clear explanation of what had become part of the official case file.
In other instances, court papers that were reportedly reviewed by a court were later marked as “replaced” in docket entries, without a corresponding motion or court order authorizing replacement of the principal filings in the case.
At the same time, several published expert reports allege that cyber threat actors have exploited this systemic weakness to manipulate the course of judicial proceedings and effectively counterfeit court outcomes for profit or other strategic gain.
In its October 22, 2025, report, e-Forensic Integrated Expert Report: Anatomy of the Strategic cAPTure-to-Kill Operation, Cyber-N.E.T. Forensics (“CNF”) defines this alleged advanced persistent threat as a “coordinated cyber campaign targeting attorneys, law firms, and judicial infrastructure to manipulate active court proceedings.”
Although attorneys and law firms have long been targets of cyberattacks, CNF and other independent experts report that the dynamics of the alleged cAPTure operation have been used to eliminate, disrupt, or manipulate judicial outcomes through existing malicious infrastructure, established footholds within legacy court endpoints and servers, and commonly used tactics, techniques, and procedures, or TTPs.
In this model, the first objective is not ransomware. It is access. The attacker studies routines, obtains or abuses credentials, maps clerk workflows, monitors public dockets, probes older servers, learns how bar and court portals route filings, and identifies where notices, service lists, and document records are maintained.
The second objective is timing. The attacker waits for a deadline, hearing, sealing request, emergency motion, disciplinary response, default risk, or protective filing that makes intake decisive.
The third objective is plausible deniability. The system may still appear to function. The portal loads. The padlock remains green. Email authentication may pass. The docket prints. Yet the failure may be embedded in routing, sequence, recipient identity, document completeness, case association, or notice timing.

Why the problem must be understood as court access, not merely information security
A modern court or bar-regulatory body operates as an intake machine. Mail is opened, scanned, sorted and routed. Emails move through staff accounts, assistants, counsel, intake units and IT security. Hand-delivered paper may be digitized before review.
Complaints, responses, exhibits, forensic reports and emergency communications often pass through shared drives, vendor tools, departmental handoffs and service lists. An adversary does not need every office. It needs one trusted handoff.
The forensic record reviewed here includes multiple streams. In its December 5, 224 Expert Report, Marlin Technologies diagnosed an advanced persistent threat affecting a legal professional’s endpoints, DNS, email and cloud access. CNF’s integrated reporting describes DNS and MX manipulation across law-related domains and compares portal-infiltration datasets from bar and court environments.
CCDG focused on cryptographically aligned counterfeit communications: messages that may pass SPF, DKIM and DMARC while still being operationally false because the trusted relay, signing process, DNS path, vendor account or service-list route has been compromised. RAPS analyzed restricted-access portals at the authentication layer, workflow layer and internal routing layer, including observable effects such as missing or truncated filings, misrouted notices and assignment anomalies.
The overlap matters. These teams did not merely report “strange emails.” They described a layered pattern: DNS authority shifting, mail routes moving, credentials being used where they should not be, portal events appearing during rogue windows, case identifiers breaking at critical moments, and notices showing superficial authentication while carrying anomalous content, timing, attachments or recipients.

Why Paper Filing Is No Longer Truly ‘Out of Band’
One source-document anomaly is simple enough for any reader to understand. In a Florida state high-court matter, a filing made in an existing case returned an e-filing receipt showing the case number as UNKNOWN. A later processing notice for the same filing showed a 99-series placeholder, “Not Docketed,” and a notation that it had been manually docketed into the known case.
Case numbers are not decoration. They are routing commands. They determine where a filing lands, who receives notice, whether a deadline is preserved and whether the judge sees the document as part of the record. A known case returning UNKNOWN, or a placeholder case number, should trigger preservation and log review rather than casual treatment as clerical noise.
Another reviewed sequence involved paper. After an electronic filing was rejected, the filer hand-delivered a corrected response. The record reviewed for this release states that the response was 34 pages, but the version later visible in the electronic record appeared to stop around page 20 or 21.
A clerk order then required electronic filing and warned of sanctions for future non-electronic filing. That is the loop in miniature: the filer says the electronic route is compromised; the filer uses paper; the paper becomes digital; the digital version is allegedly incomplete; the system tells the filer to use the electronic route.

Court E-Service Communications – Authentication Is Not Authenticity
E-Service presents a third category. The legal community often treats a court notice as trusted because it appears to come from the court and because technical authentication checks pass. That assumption is no longer sufficient in a compromised environment.
SPF can confirm that a sending server is authorized. DKIM can confirm that a message was signed by a valid key. DMARC can instruct receiving systems how to handle failures. But those controls do not prove institutional truth when an adversary controls or compromises the authorized relay, DNS record, signing process, vendor account, portal credential or service-list path. In that posture, a green check can become part of the deception.
Authentication proves a path. It does not prove that the content, timing, recipient list, attachment, case identity or institutional act is genuine.

The Emergency Entrance
The federal side presents the same structural concern. Restricted-access portals are places where identity, workflow and trust converge: court e-filing, licensing, tax, benefits, banking and professional-regulatory systems. When a conventionally filed or sealed document is scanned into a legacy digital environment, the document has not necessarily remained outside the attack surface. It may have been moved from the courthouse counter into the same electronic system whose integrity is in question.
The playbook is adaptable. It can apply to a family-court emergency, a small-business injunction, a sealed whistleblower complaint, a criminal protective filing, a bar response, a housing case, a licensing dispute or an appeal. Digital systems do not distinguish between powerful and powerless litigants. Once intake is compromised, the person with the least technical capacity usually suffers first and worst.
A national firm may have redundant email, managed devices, incident-response counsel and direct institutional contacts. A small firm, solo attorney, pro se litigant or licensed professional under regulatory pressure may have only the portal, the service list and a clerk counter that still feeds the portal. Larger institutions are not immune.
Threat actors can exploit individual digital footprints, abused credentials and organizational assumptions to create the illusion that a communication, filing or firm relationship is legitimate when it is not. In a multi-office environment, default trust between apparent colleagues can itself become an exploitable path.
This should not be framed as a complaint against courts, clerks, judges, bar associations, lawyers or vendors. Courts and clerks are also victims of this design problem.
They were handed fragmented systems, local practices, legacy servers and vendor-dependent workflows, then asked to make them function as the legal system’s memory. Federal districts maintain separate CM/ECF instances.
State systems depend on statewide portals, local clerks, bar organizations, relays, document-management tools and cloud services. Fragmentation helps attackers. They can research each workflow, identify the weak handoff, wait for a trigger event and use one compromised credential or routing point to start a procedural cascade.
Even official-looking domains and emails do not settle the trust question. In some environments, public-facing .gov or .org addresses depend on aliases, cloud systems, inherited infrastructure, vendor routing or legacy records. Users may place high trust in what they believe they are seeing without understanding where the domain resolves, who controls the authoritative records, or how the notice was actually generated.
That is why the phrase “emergency entrance” matters. Courts have emergency procedures for fires, storms, physical closures, death-penalty filings, protective orders and midnight injunctions. What appears to be missing is a uniformly recognized cyber-emergency intake lane that bypasses the disputed rail long enough for a neutral judicial officer to authenticate the record.

The Containment Protocol – Achieving Meaningfully Timed Containment
The goal of experts we interviewed is for any cyber-crime victim to obtain meaningful relief – containment before the cyber-investigation is within the ‘search and recovery’ and well before the cyber-autopsy.
Threat actors have discovered and exploited the convergence of every lane to a court of law, with few exceptions in many state and seemingly all federal jurisdictions, is digitalization of the court document and electronic routing to the court and thereafter e-service to the ‘parties.
The absence of any direct access to a judge for purposes of presenting evidence of being targeted by threat actors gives threat actors a repeatable sequence.
- First, identify valuable cases, lawyers, litigants or regulatory matters.
- Second, obtain or abuse credentials from attorneys, staff, vendors or portal users.
- Third, monitor dockets for trigger events: sealed motions, emergency relief, forensic reports, complaints naming cyber interference, disciplinary responses, TRO requests or appeals.
- Fourth, act inside the intake layer during the narrow window before judicial review.
- Fifth, rely on institutional presumptions: the docket is accurate, service was sent, the case number routes correctly, paper was scanned faithfully and authenticated mail is authentic.
Comparator cyber-disruption matters show that modern threat actors reuse infrastructure, abuse trusted services, operate botnets, deploy unauthorized or cracked tools, and pivot across domains, IP ranges, cloud services and relays when disrupted.
The September 8, 2025 order in Microsoft, Fortra and Health-ISAC’s Eastern District of New York case against John Doe defendants associated with Conti, LockBit and related groups is not proof that every downstream court anomaly has the same source. It is a comparator showing the kind of infrastructure, tradecraft and court-supervised response mechanisms already confronting the judiciary.
None of the reports review suggests that every court anomaly proves the same actor or that any judge, clerk, bar employee, lawyer or vendor intentionally participated in wrongdoing, in fact, quite the opposite in that to the extent that one or more anomaly points to a pattern of compromise, it is the threat actors and not those laboring within the judicial system in their official capacity are at fault.
Thus, the victims are not just the primary targets, but all those trusting e-communications, e-Portals, e-service or court related emails. However, at some point, experts warn that simply ignoring the possibility of compromise without some reasonable practices to verify authentic communications likely will cause the cAPTure cyber attack to have continued success as even upgrades to court cyber-infrastructure cannot replace an out of band channel for a party to litigation to reach a judicial officer during a cyber emergency designed to interfere with communication channels.
Simply put, if threat actors can exploit trusted workflows, good-faith institutional actors can unknowingly act on corrupted inputs. A clerk sees a deficient filing. A tribunal sees no response. A party receives no notice. A judge sees a docket that appears complete. The injury occurs before merits review.
The solution is not to abandon electronic filing. It is to stop pretending that electronic filing can also be the only emergency path when electronic filing is the evidence.
Courts and bar-regulatory bodies need a cyber-emergency intake protocol. It should be narrow, documented and hard to abuse.
- It should allow a litigant, lawyer or regulator who presents threshold cyber-integrity evidence to place material before a judge, special master or designated cyber-integrity officer through an out-of-band route.
- It should require immediate preservation of portal logs, service-list histories, SMTP headers, DNS records, access tokens, document hashes, file-size records, scan logs and clerk-intake notes. It should freeze disputed service lists.
- It should compare hand-delivered originals against scanned versions. It should permit temporary paper-only or in-camera handling for sensitive forensic evidence. It should prohibit default, dismissal, discipline, sanctions or adverse deadline consequences until disputed intake events are authenticated.
This is not special treatment. It is chain of custody ensuring the integrity of litigants receiving due process and, as important, protecting the integrity of courts of law and the results which are digitally uploaded to ‘official dockets’.
The modern justice system depends on records. If the record is attacked before the judge sees it, the legal system must have a way to examine the record without forcing the victim back through the compromised route.
That principle protects everyone: large firms and solo lawyers, prosecutors and defendants, civil plaintiffs and corporations, courts and clerks, regulators and the public. It also protects judges and clerks by separating human decision-making from the contested data stream before innocent officials rely on poisoned inputs during moments when seconds matter.
The digital courthouse was built for efficiency. It now needs resilience. A filing system that can receive every document but cannot safely receive a warning that the filing system is compromised is not a courthouse door. It is a trap.
The evidence will not be resolved by volume or rhetoric. It will be resolved by logs, hashes, headers, timestamps, file-size comparisons, DNS histories, source-document overlays and controlled intake outside the contested rail. The next cyber emergency should not depend on whether a victim can persuade the very system under attack to deliver the warning.
And, if threat actors can not only disrupt the normal flow of judicial digital processes, they decide when, what or if a court ever sees the very evidence which is preventing a party from obtaining true due process of law under the rule of law. In so doing, they leave in their wake what appears to be a case going through its normal course, however it is they, who counterfeit the record and ultimately have the power to control the judicial result.
The Path Forward – Create Non-Digital Channels to Judicial Relief
The clear path forward here, is fairly straight forward and logistically within immediate reach. The promulgation of court rules which provide for a process to bypass digitalization of a court filing with respect to issues related to the adjudicative environment – in short – open an out of bound emergency court entrance such that judicial power can interceded to protect the integrity of the proceedings, the court’s own jurisdiction and the confidence our nation has in judicial results.

About the Author – Jay Lewis Farrow
Jay Lewis Farrow is a legal-sector cybersecurity analyst, writer, and training developer whose work focuses on advanced persistent threats affecting attorneys, law firms, judicial and quasi-judicial infrastructure, court-clerk operations, and legal-industry supply chains.
Farrow, working with national and international cybersecurity professionals and organizations who participate within the Joint Cyber Defense Collaborative ecosystem, has contributed to published forensic expert reports and published analysis addressing litigation forensics, endpoint analysis, DNS hijacking, cloud-service abuse, counterfeit communications, restricted-access portals, professional-identity risk, evidence preservation, and strategic incident response.
He is the founder and chair of the National Attorneys Cybersecurity Association (NACABAR) and serves as its CLE course developer and featured speaker for a Florida Bar-Accredited Technology CLE course. Additional content and materials by Jay Lewis Farrow can be found on NACABAR YOUTUBE CHANNEL, NACABAR FACEBOOK PAGE, and on NACABAR INSTAGRAM.